A new security study has found that 548 internet-exposed building automation devices near U.S. data centers are running end-of-life products that will not receive future security patches.
The affected devices belong to three legacy product lines: Tridium NiagaraAX 3.x, Trane Tracer SC, and Carrier WebCTRL version 7.0.
These platforms are used to manage systems such as HVAC, cooling, power monitoring, and environmental controls. In a data center, a compromise of these systems could affect the physical infrastructure that keeps servers online.
The finding comes from a wider scan of industrial control system (ICS) and building automation system (BAS) devices located near more than 1,000 U.S. data center locations.
Researchers identified 6,300 high-confidence internet-accessible devices, including BACnet controllers, Niagara platforms, programmable logic controllers, and power-management interfaces.

Building automation was the main exposure point. BACnet devices accounted for 58% of the findings, while Fox/Niagara systems represented 23%.
Together, the two technologies made up 81% of the exposed systems in the dataset. These protocols were largely designed for trusted internal networks and often lack modern authentication and encryption protections.
548 Building Devices Unpatched
End-of-life products present a serious security problem because organizations cannot rely on vendor patches when new vulnerabilities are found.
The research mapped 53 CVEs across 10 vendor platforms, including seven vulnerabilities with CVSS scores of 9.8 or higher.
One of the critical findings involved 434 NiagaraAX devices. NiagaraAX is a legacy Tridium platform that has reached end of life.
The report says these systems may be vulnerable to CVE-2012-4701, a flaw that can enable directory traversal and remote code execution.
Trane Tracer SC devices were also identified as end of life and linked to CVE-2021-38450, an authenticated remote code execution issue with a CVSS score of 9.9.
Carrier WebCTRL 7.0 devices were another concern. The study identified 64 devices using the unsupported version, which is affected by CVE-2024-8525.

The vulnerability has a CVSS score of 10.0 and could allow unauthenticated remote code execution through file upload.
The wider dataset also contained 237 Delta Controls enteliBUS controllers vulnerable to CVE-2019-9569, an unauthenticated remote code execution flaw involving crafted BACnet traffic.
Although a patch has been available for years, the continued presence of exposed devices shows how difficult OT and BAS patch management can be.
Unlike a normal IT system, a building automation controller can directly influence physical processes.
A compromised BAS device could allow an attacker to change temperature or humidity settings, disable cooling equipment, disrupt alarms, or lock out facilities personnel, trendaisecurity said.
This creates a major risk for data centers, where cooling failures can quickly trigger thermal alerts and service interruptions.
Systems from vendors such as Vertiv and Liebert are particularly important because they are designed for precision cooling, uninterruptible power supply management, and power distribution.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR